Batch #3 - August 2026 (8 advisories · 8 critical · 8 unauth)
·
6 commits
to main
since this release
Batch #3 — August 2026
8 advisories · 8 vendors · every advisory ships a full root-cause analysis + a working, reproducible PoC.
Third batch — expanding coverage into data platforms, SCADA, BI/reporting, and IoT/embedded systems. Full writeups on https://0day-rubbish.com/blog; PoC code under product/<vendor>/<version>/<type>/exploit/.
| # | Product | Affected Version | CVSS | Class | Advisory & PoC |
|---|---|---|---|---|---|
| 1 | Confluent Platform | 7.9.1-ce | 9.8 | Unauth RCE (Root) | ksqlDB CREATE SINK CONNECTOR → RCE |
| 2 | Ontotext GraphDB | 11.4.3 | 9.8 | Unauth RCE (Root) | .pie Ruleset Prefix Injection → RCE |
| 3 | ObjectDB | 2.9.5 | 9.8 | Unauth RCE (Root) | JDOQL Filter Injection → RCE |
| 4 | Wyn Enterprise | 9.1.00145.0 | 9.8 | Unauth RCE (Root) | Token Forgery + Zip-Slip + Provider Load → RCE |
| 5 | MAPS SCADA | 4.0.5.5 | 9.8 | Unauth RCE (SYSTEM) | BinaryFormatter Deserialization → RCE |
| 6 | DataStax Enterprise | 6.8.49 | 9.8 | Unauth RCE | Gremlin-Groovy Sandbox Bypass → RCE |
| 7 | nanoDLP | stable #10729 | 9.8 | Unauth RCE (Root) | G-code Injection → RCE |
| 8 | iMonnit Express | 4.0.5.5 | 9.8 | Unauth RCE (SYSTEM) | Auth Bypass + Path Traversal + Plugin Load → RCE |
Highlights
- 8 critical (CVSS ≥ 9.0) · 8 unauthenticated
- Notable: Confluent ksqlDB → cron root RCE, DataStax Gremlin-Groovy sandbox bypass, and an OT/SCADA SYSTEM RCE (MAPS SCADA)
- Attack classes: code injection, JDOQL injection, deserialization, sandbox bypass, G-code injection, plugin dynamic loading
Running total
35 advisories · 26 vendors · 29 critical · 28 unauthenticated · all with reproducible PoC.
Next drop: weekly → expanding into ICS / SCADA, energy, and aerospace.
⭐ Star to bookmark · 👁 Watch for the next batch · 🌐 https://0day-rubbish.com/blog